Skip to main content
mariocova
New Member
February 10, 2020
Question

VPN NAT source IP

  • February 10, 2020
  • 4 replies
  • 3778 views

Hi,

 

Maybe this thread is very basic but after reading a lot of documentation I can't determine how to solve it.

We are trying to setup a VPN to reach our customer.  

 

The client asked us to NAT our internal subnet (10.120.30.0/24) to the IP 172.40.239.121. To have the VPN up and running we created a policy with source 172.40.239.121 and destination the IP addresses of the internal subnet of our customer. The tunnel is now UP however we don't really know how to nat our internal subnet (10.120.30.0/24) to the IP 172.40.239.121.

 

can you please guide us ?

 

Thanks in advance

 

FortiGate 100E v6.0.2 build0163 (GA)

 

 

 

 

4 replies

rwpatterson
New Member
February 10, 2020

If that IP is not being used anywhere in your environment, you could create a IP pool with that one address and assign it to the policy. I have see IP pool entries killing that existence of the IP in other places in the firewall in the past. Use with testing and caution.

emnoc
New Member
February 10, 2020

Yes a ippool is ideal;

 

config firewall policy edit 1892 set srcintf "LAN1" set dstintf "PUPVPN" set srcaddr "NET01" "NET02" "NET03" set dstaddr "CUST788_REMOTE-028"" set action accept set schedule "always" set service "ALL" set ippool enable set poolname "CORP-to-CUSTID788" set nat enable next

end

 

Ken Felix

mariocova
mariocovaAuthor
New Member
February 10, 2020

Hi ,

 

Thanks for your reply.

 

In your example the srcaddr "NET01" "NET02" "NET03" is related with our internal subnet and dstaddr "CUST788_REMOTE-028"" is about customer subnet ? Where is done the NAT between our internal subnet and the NAT IP that we should use ? 

 

Thanks

 

mauros
New Member
February 28, 2020

Jumping in since I have the same problem: with the customer we agreed for two ip-pools (one per side) and I could configure that on my side, but they asked to hide that pool behind a specific ip of that pool... how can I obtain that configuration?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!